{"id":29512,"date":"2023-11-18T19:07:21","date_gmt":"2023-11-19T00:07:21","guid":{"rendered":"https:\/\/www.oxebridge.com\/emma\/?p=29512"},"modified":"2023-11-18T19:28:01","modified_gmt":"2023-11-19T00:28:01","slug":"ringcentral-stores-users-credit-card-information-in-pile-of-paper-by-fax-machine","status":"publish","type":"post","link":"https:\/\/www.oxebridge.com\/emma\/ringcentral-stores-users-credit-card-information-in-pile-of-paper-by-fax-machine\/","title":{"rendered":"RingCentral Stores User&#8217;s Credit Card Information in Pile of Paper by Fax Machine"},"content":{"rendered":"<p>Forget two-factor authentication. Forget storing crucial data using a SHA-256 hashing algorithm. Videoconferencing provider <a href=\"https:\/\/www.ringcentral.com\/\">RingCentral<\/a> has decided to go analog, and keep users&#8217; credit card information in a big pile of papers next to their 1990 Brother fax machine, probably nar a half-empty box of those <a href=\"https:\/\/www.kroger.com\/p\/entenmann-s-devil-s-food-crumb-donuts\/0007203000131\">Entenmann donuts that look like they have rabbit droppings on them<\/a>.<\/p>\n<div id=\"attachment_29513\" style=\"width: 310px\" class=\"wp-caption alignright\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-29513\" class=\"wp-image-29513 size-full\" style=\"border: 1px solid #000000;\" src=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/11\/181458868_fax-machine-brother-intellifax-600-fax.jpg\" alt=\"\" width=\"300\" height=\"225\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/11\/181458868_fax-machine-brother-intellifax-600-fax.jpg 300w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/11\/181458868_fax-machine-brother-intellifax-600-fax-150x113.jpg 150w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/11\/181458868_fax-machine-brother-intellifax-600-fax-200x150.jpg 200w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><p id=\"caption-attachment-29513\" class=\"wp-caption-text\">RingCentral&#8217;s cybersecurity firewall.<\/p><\/div>\n<p>Recently, a client of mine sent me an invite for an upcoming web meeting. Instead of using Teams or Zoom, this client uses RingCentral. In the invite, I was prompted to create a RingCentral account so I could access the meeting. Fortunately, I already had a RingCentral account, since another client of mine used it &#8212; back in 2005 or so.<\/p>\n<p>As expected, my login didn&#8217;t work, when I tried to use the old password. So, I clicked &#8220;<em>forgot password<\/em>,&#8221; and RingCentral sent me a link to reset my password. Clicking that, I was sent to the original &#8220;<em>login<\/em>&#8221; page&#8230; without any ability to enter a new password. Dead end.<\/p>\n<p>I tried different browsers, just to be sure, but no luck. I also tried with and without VPN, just to be sure my non-US IP wasn&#8217;t causing problems. Nope.<\/p>\n<p>So I used a different email address to create account, but that also left me in a loop. I just couldn&#8217;t get this to work. But I tend to have my security settings cranked up pretty high here, so that is known to cause issues with some websites.<\/p>\n<p>Suddenly, though, I received an email from RingCentral, but to the address I used to create the original account from years ago. It said my account &#8220;<em>required attention&#8221;<\/em> because they were unable to verify my financial information. I don&#8217;t know why they <em><strong>needed<\/strong> <\/em>my credit card info to join a free RingCentral meeting hosted by my client, but whatever. And yeah, sure, whatever credit card they had on file years ago was, no doubt, long since expired.<\/p>\n<p><span style=\"font-size: 14pt;\"><strong>No, You&#8217;re Not Dreaming This<\/strong><\/span><\/p>\n<p>Now, before you read this next sentence, I want you to remember you are reading this in the year <em><strong>2023<\/strong><\/em>, when AI and quantum computers already exist.<\/p>\n<p>In its email, RingCentral asked me to send <em><strong>photocopies of my driver&#8217;s license along with scanned copies of the front and back of my credit card to them &#8230; by fax machine.<\/strong><\/em><\/p>\n<p>Did I mention we currently live in 2023, and that we now have commercial drones and electric cars and fully-automated 3D printers?<\/p>\n<p>I know you don&#8217;t believe me, so here it is:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-29514\" style=\"border: 1px solid #000000;\" src=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/11\/ringcentraloncrack.jpg\" alt=\"\" width=\"600\" height=\"710\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/11\/ringcentraloncrack.jpg 1320w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/11\/ringcentraloncrack-127x150.jpg 127w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/11\/ringcentraloncrack-768x909.jpg 768w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/11\/ringcentraloncrack-1297x1536.jpg 1297w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/11\/ringcentraloncrack-1080x1279.jpg 1080w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/11\/ringcentraloncrack-560x663.jpg 560w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/>And, yes, I verified it wasn&#8217;t a phishing scam. This was legitimate.<\/p>\n<p>The idiots had the balls to say that &#8220;<em>credit card fraud accounts for $2 billion annually,&#8221; <\/em>and this was all necessary to ensure RingCentral could<em> &#8220;do our part to help reduce this figure and create a safe environment for you.<\/em>&#8221;<\/p>\n<p>OH.<\/p>\n<p>MY.<\/p>\n<p>GOD.<\/p>\n<p>Think about what this means. Somewhere over in their San Francisco office (area code 650), there is a stack of faxed credit card authorization forms sitting there, entirely unprotected and available for viewing by any schlub who walks past the 1990s fax machine.<\/p>\n<p><em><strong>So<\/strong> <\/em>unprotected, in fact, that not only is your credit card information at risk of being seen by anyone, it&#8217;s at risk of getting <em><strong>coffee<\/strong> <\/em>spilled on it. And worse, NIST just updated 800-171 and didn&#8217;t even address proper cybersecurity controls for coffee spills.<\/p>\n<p><span style=\"font-size: 14pt;\"><strong>You Knew There Was an ISO Certificate Here Somewhere<\/strong><\/span><\/p>\n<p>Oh, we&#8217;re not done yet. Not by a long shot.<\/p>\n<p>RingCentral holds <a href=\"https:\/\/assets.ringcentral.com\/us\/report\/iso-27001_award.pdf\">ISO 27001 information security management certification<\/a> issued by none other than Coalfire. Because <em><strong>of course<\/strong><\/em> they fucking do.<\/p>\n<p><a href=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/11\/iso-27001_award_Page_1.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-29518\" style=\"border: 1px solid #000000;\" src=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/11\/iso-27001_award_Page_1.jpg\" alt=\"\" width=\"600\" height=\"765\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/11\/iso-27001_award_Page_1.jpg 1700w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/11\/iso-27001_award_Page_1-118x150.jpg 118w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/11\/iso-27001_award_Page_1-768x979.jpg 768w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/11\/iso-27001_award_Page_1-1205x1536.jpg 1205w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/11\/iso-27001_award_Page_1-1607x2048.jpg 1607w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/11\/iso-27001_award_Page_1-1080x1377.jpg 1080w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2023\/11\/iso-27001_award_Page_1-560x714.jpg 560w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p>You might recognize the name Coalfire as being one of the noisiest CMMC C3PAO assessors polluting your LinkedIn feed with their incessant droning.<\/p>\n<p>Now, I&#8217;m no ISO 27001 expert &#8212; I only help <em><strong>set up<\/strong><\/em> ISO 27001 certification bodies like Coalfire against ISO 17011 &#8212; but I&#8217;m pretty sure none of the controls listed in 27006 allow for printed data sitting on fax machines.<\/p>\n<p>In response to my <a href=\"https:\/\/www.linkedin.com\/posts\/oxebridge_hey-ringcentral-i-would-fire-your-crack-activity-7131343701464748033-6xj4?utm_source=share&amp;utm_medium=member_desktop\">calling him out on LinkedIn<\/a>, RingCentral&#8217;s CISO <a href=\"https:\/\/www.linkedin.com\/in\/marmer\/\">Michael Armer<\/a> promised that his &#8220;<em>team is looking into this<\/em>.&#8221;<\/p>\n<p>Hey, want to know how your team can look into it? <em><strong>WALK DOWN THE FUCKING HALLWAY AND LOOK FOR THE FAX MACHINE WITH THE PILES OF CREDIT CARD FORMS SPITTING OUT OF IT.<\/strong><\/em><\/p>\n<p>Sometimes I can&#8217;t believe I actually live on this planet.<\/p>","protected":false},"excerpt":{"rendered":"<p>Oh, and they have ISO 27001 certification from Coalfire, because, of course.<\/p>","protected":false},"author":2,"featured_media":29515,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","mc4wp_mailchimp_campaign":[],"footnotes":""},"categories":[157,5],"tags":[7679,8123,938,65,954,8402],"class_list":["post-29512","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-humor-2","category-opinion","tag-cmmc","tag-coalfire","tag-cybersecurity","tag-iso-27001","tag-nist","tag-ringcentral","et-has-post-format-content","et_post_format-et-post-format-standard"],"_links":{"self":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/29512","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/comments?post=29512"}],"version-history":[{"count":5,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/29512\/revisions"}],"predecessor-version":[{"id":29521,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/29512\/revisions\/29521"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media\/29515"}],"wp:attachment":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media?parent=29512"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/categories?post=29512"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/tags?post=29512"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}